CVE-2020-35563: XSS
Published Feb 16, 2021
·Updated
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
Affected Software
2 affected components
Mbconnectline Mbconnect24<=2.6.2
Mbconnectline Mymbconnect24<=2.6.2
Event History
Feb 16, 2021
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24?
The vulnerability ID for this issue in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 is CVE-2020-35563.
2
What is the severity of CVE-2020-35563?
The severity of CVE-2020-35563 is medium (5.4).
3
What is the affected software for CVE-2020-35563?
The affected software for CVE-2020-35563 is MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 version up to 2.6.2.
4
What is the CWE category for CVE-2020-35563?
The CWE category for CVE-2020-35563 is CWE-79 (Cross-Site Scripting).
5
How can an attacker exploit CVE-2020-35563?
An attacker can exploit CVE-2020-35563 by injecting crafted malicious code into the page through an incomplete XSS filter.